Remote Code Execution Vulnerability in Backstage TechDocs by Spotify
CVE-2026-106510

7.7HIGH

Key Information:

Vendor

Backstage

Vendor
CVE Published:
7 October 2026

What is CVE-2026-106510?

An issue exists in the @backstage/plugin-techdocs-node package affecting Backstage prior to version 1.14.6, where an authenticated user with the ability to register catalog entities can exploit crafted markdown extensions in the techdocs mkdocs.yml. This vulnerability allows for arbitrary operating system command execution on the TechDocs build host during the documentation build process.

Affected Version(s)

backstage < 1.50.5 < 1.50.5

backstage >= 1.51.0-next.0, < 1.54.6 < 1.51.0-next.0, 1.54.6

plugin-techdocs-node < 1.14.6 < 1.14.6

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.